Law / United States / Texas

Cybersecurity Program safe harbor from exemplary damages (S.B. 2610)

Tex. Bus. & Com. Code ch. 542 (secs. 542.001-542.004)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 September 2025.

A security baseline statutes rule binding private bodies.

As of 12 September 2026.

What it requires

  • This chapter applies only to a business entity with fewer than 250 employees that owns or licenses computerized data including sensitive personal information, as those terms are defined by Section 521.002.
  • It is a safe harbor, not a duty: if such an entity is sued over a breach of system security and demonstrates that, at the time of the breach, it had implemented and maintained a cybersecurity program meeting Section 542.004's requirements, the claimant may not recover exemplary damages from it. A qualifying program must contain administrative, technical, and physical safeguards; conform to a named industry-recognized cybersecurity framework (the NIST Cybersecurity Framework, NIST SP 800-171, NIST SP 800-53/53A, the FedRAMP Security Assessment Framework, the CIS Critical Security Controls, the ISO/IEC 27000-series, the HITRUST Common Security Framework, the Secure Controls Framework, SOC 2, or a similar framework); and be scaled by headcount: simplified measures such as password policies and employee training below 20 employees, the CIS Controls Implementation Group 1 from 20 to 99 employees, and full conformance with a named framework from 100 to 249 employees.
  • The chapter creates no duty to adopt a program and no cause of action of its own; it only removes exemplary-damages exposure for a qualifying entity that already has one at the time of a breach.

What it reaches

Obligation class

Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A business entity with fewer than 250 employees that owns or licenses computerized data including sensitive personal information may invoke a safe harbor from exemplary damages. In an action arising from a breach of system security, such an entity may not be held liable for exemplary damages if it demonstrates that, at the time of the breach, it had implemented and maintained a cybersecurity program conforming to a named industry-recognized framework and scaled to its size. The chapter creates a safe harbor from a category of damages, not a freestanding duty to adopt a program.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
  • serves_minors
  • operates_social_platform
  • ships_mobile_app
  • distributes_software_product

Read the law

Official statute text, Texas Business and Commerce Code, Cybersecurity Program (S.B. 2610, 2025)

Back to the example  ·  Lint your app